Access guide · clearnet to Tor · 2026

How to Access WeTheNorth Safely

Reaching WeTheNorth is a short trip with two checkpoints. You start here, on the clearnet. You carry the signed onion across into Tor. Then a PGP check proves that address is the real market before you type a single thing. Skip the order and a look-alike page can grab your login on the first try. This guide walks the whole run.

Canon pointerRather than repeat the register here, this walkthrough sends you back to one source of truth. The address you copy and every mirror we sign live on the canon, checked against a single key.hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion
The handofftwo checkpoints

The bridge from an open browser to a real login

Almost every bad login begins the same way. Someone jumps from a search box straight to the password field. The safe route drops two checks into that gap. This is the shape before the steps.

Access handoff: you start on this clearnet page, take the verified onion across into Tor, and reach the WeTheNorth market only after the signature checks.Clearnetthis pageHandoffverify + carryOnionWTN market
Start on clearnetThis page lives on the open web so a search can find it. All it hands you is a checked address.
Carry and verifyYou move the onion into Tor and test it against the PGP signature, not against how convincing the page looks.
Reach the marketOnly an address that cleared the check gets your login, and only inside Tor Browser.
Step by stepfollow in order

Five steps to reach WeTheNorth without touching a clone

  1. Boot Tails, or set Tor Browser to Safest. With scripts off, a hostile mirror loses most of its tricks.
  2. Grab the canon PGP key before you glance at any address. That key is the yardstick for every link after it.
  3. Pull the signed register, run the signature check, and confirm the fingerprint is the one you already hold.
  4. Copy the onion off the verified box. Do not retype it, and do not trust a link from search, a forum, or a chat.
  5. Load it in Tor, clear the captcha, then log in. Keep this identity walled off from your real name.

The captcha before the login box is normal and slows bots. A page that skips it and asks for money up front is not WeTheNorth.

Key importstep two, up close

How do you import the key and check a signature?

Step two is the one people skip, so here it is in full. You import the published key once. After that you use it to test the signature shipped next to the register. If the test passes, the list is genuine and the address inside it is safe to copy. If it fails, you stop right there.

gpg --import wethenorth-canon.asc
gpg --verify mirrors.json.sig mirrors.json

A pass reads as a good signature from the canon key. Then compare the printed fingerprint against the one you trusted the first time. New to this? Start on the signed canon, where the key and directory live.

Honest limit. We hand you the method, we cannot police your machine. A hijacked clipboard or a stale bookmark can still aim you at the wrong host, so run the check every time.

Questionsplain answers

Access questions people actually ask

Do I need Tails, or is Tor Browser enough?

Tor Browser at the Safest level covers most people. Tails adds a system that forgets everything on shutdown, which is worth it if you want no local trace.

Why import the key before I look at a link?

Read the address first and you are tempted to trust it before you can test it. Holding the key first means every candidate gets judged, not just the ones that look off.

My address is a couple of characters off. Still usable?

No. One wrong character is a different server, which here usually means a clone. Discard it and copy a clean one from the register.

Related

Next moves

Holding a link and want to test it, or heading straight for sign in? Pick up the thread. The status page explains the probe states you will see.

Read the login notes